Overview
The GRC Analyst will play a pivotal role in enhancing cyber and technology risk management within a leading global organization. This contract position involves collaborating with various stakeholders to build and embed a robust risk function, ensuring effective identification, assessment, reporting, and management of technology and cyber risks. The Analyst will engage closely with senior leadership and will thrive in a hybrid working environment.
Responsibilities
- Build, develop, and maintain cyber and technology risk registers.
- Identify, assess, and document risks across technology, cyber security, and business change initiatives.
- Produce clear risk statements covering threats, vulnerabilities, business impact, and existing controls.
- Develop and maintain risk treatment plans, ensuring actions are owned and delivered.
- Track remediation activities and challenge overdue actions where required.
- Facilitate risk reviews and workshops with technical and non-technical stakeholders.
- Support Cyber Assessment Framework (CAF) activities, evidence gathering, and remediation tracking.
- Produce high-quality risk reporting and management information for senior leadership.
Requirements
- Proven experience as a GRC Analyst, Technology Risk Analyst, Cyber Risk Analyst, or Information Security Risk Analyst.
- Strong practical experience owning and maintaining risk registers.
- Demonstrable experience conducting risk assessments and developing risk treatment plans.
- Ability to write meaningful risk statements and present complex risks clearly.
- Strong stakeholder management skills with the confidence to operate independently from day one.
- Experience tracking remediation and mitigation activities through to completion.
- Excellent communication and reporting skills.
- Familiarity with NCSC Cyber Assessment Framework (CAF), ISO 27001, and NIST Cybersecurity Framework.